XIAOBA 2.0 Ransomware – Remove + Recover .XIAOBA Files

This article has been created with the purpose to help explain what is the 2.0 version of Xiaoba ransomware virus and how to remove it from your computer plus how you can restore .XIAOBA files.

A new variant of the Xiaoba ransomware virus has been detected by security researcher Rony. The ransomware infection’s primary purpose is to encrypt the files of importance on the PC’s infected by it and then add the .XIAOBA suffix to them plus drop a “File Recovery Guide” decryption instructions. Their goal is to get the victim to pay a hefty ransom of 0.5 BitCoin in order to get their important files to open again. If your computer system has been victimized by XIAOBA 2.0 ransomware, we advise that you read this article as it will help you to remove this malware from your computer and try restoring your files.

Threat Summary

NameXIAOBA 2.0
TypeRansomware, Cryptovirus
Short DescriptionNew variant of Xiaoba ransomware. Encrypts files and then asks for 0.5 BTC to be paid as ransom to see your files working again.
SymptomsThe XIAOBA 2.0 Ransomware ads the .XIAOBA extension to the encrypted files and drops a “File Recovery Guide”.
Distribution MethodSpam Emails, Email Attachments, Executable files
Detection Tool See If Your System Has Been Affected by XIAOBA 2.0

Malware Removal Tool

User ExperienceJoin Our Forum to Discuss XIAOBA 2.0.Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

XIAOBA 2.0 Ransoware – Infection Methods

The main infection that is conducted (Read more...)

*** This is a Security Bloggers Network syndicated blog from How to, Technology and PC Security Forum | SensorsTechForum.com authored by Vencislav Krustev. Read the original post at: https://sensorstechforum.com/xiaoba-2-0-ransomware-remove-recover-xiaoba-files/